Описание
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.27 (исключая)
cpe:2.3:a:10web:image_optimizer:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 30%
0.00109
Низкий
2.7 Low
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 2.7
github
больше 2 лет назад
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
EPSS
Процентиль: 30%
0.00109
Низкий
2.7 Low
CVSS3